CVE List
Id | CVE No. | Status | Description | Phase | Votes | Comments | Actions |
---|---|---|---|---|---|---|---|
9991 | CVE-2004-1563 | Candidate | Multiple cross-site scripting (XSS) vulnerabilities in w-Agora 4.1.6a allow remote attackers to execute arbitrary web script or HTML via the (1) thread parameter to download_thread.php, (2) loginuser parameter to login.php, or (3) userid parameter to forgot_password.php. | Assigned (20050220) | None (candidate not yet proposed) | View | |
9992 | CVE-2004-1564 | Candidate | CRLF injection vulnerability in subscribe_thread.php in w-Agora 4.1.6a allows remote attackers to perform HTTP Response Splitting attacks to modify expected HTML content from the server via the thread parameter. | Assigned (20050220) | None (candidate not yet proposed) | View | |
9993 | CVE-2004-1565 | Candidate | list.php in w-Agora 4.1.6a allows remote attackers to reveal the full path via a crafted HTTP request, possibly involving a malformed id parameter. | Assigned (20050220) | None (candidate not yet proposed) | View | |
9994 | CVE-2004-1566 | Candidate | Cross-site scripting (XSS) vulnerability in index.php in Silent Storm Portal 2.1 and 2.2 allows remote attackers to execute arbitrary web script or HTML via the module parameter. | Assigned (20050220) | None (candidate not yet proposed) | View | |
9995 | CVE-2004-1567 | Candidate | profile.php in Silent Storm Portal 2.1 and 2.2 allows remote attackers to gain privileges by setting the mail parameter to 1, which is the value for an administrator. | Assigned (20050220) | None (candidate not yet proposed) | View |
Page 19736 of 20943, showing 5 records out of 104715 total, starting on record 98676, ending on 98680